Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2020-14029
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the applica…
Ozeki Ng Sms Gateway
after 4.17.6
HIGH 7.5
CVE-2020-25750
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the c…
Dotplant2
2020-09-14+
CRITICAL 9.8
CVE-2020-25215
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
Yed
3.20.1+
HIGH 7.5
CVE-2020-11991EPSS 72%
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…
Cocoon
after 2.1.12
CRITICAL 9.8
CVE-2020-25257
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …
Onbase
after 20.3.10.1000
HIGH 7.5
CVE-2020-17408EPSS 74%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is n…
Expresscluster X
Patch available
CRITICAL 9.8
CVE-2020-24379
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
Ubuntu Linux
after 2.0.7
HIGH 7.1
CVE-2020-2245
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Valgrind
after 0.28
MEDIUM 6.5
CVE-2020-2247
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Klocwork Analysis
after 2020.2.1
CRITICAL 9.8
CVE-2020-25020
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
Mpxj
after 17.12
HIGH 8.3
CVE-2020-17376
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a so…
Nova
19.3.1 / 20.3.1+
MEDIUM 6.5
CVE-2020-24656
Maltego before 4.2.12 allows XXE attacks.
Maltego
4.2.12+
MEDIUM 6.5
CVE-2020-24591
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager …
Api Manager
after 5.6.0
CRITICAL 9.1
CVE-2020-24589EPSS 26%
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Api Manager
after 3.1.0
CRITICAL 9.1
CVE-2020-24052
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbi…
Exvf5c 2 Firmware
No fix yet
HIGH 8.2
CVE-2020-4481
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …
Urbancode Deploy
Mitigation only
CRITICAL 9.1
CVE-2020-4377
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…
Cognos Analytics
Mitigation only
HIGH 8.2
CVE-2020-4463EPSS 32%
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…
Maximo Asset Management
Patch available
HIGH 7.5
CVE-2020-15419EPSS 60%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…
One Firmware
9.5.4.4587 / 10.0.0.750+
HIGH 7.5
CVE-2020-15418EPSS 9%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…
One Firmware
9.5.4.4587 / 10.0.0.750+
HIGH 7.3
CVE-2020-3405
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to informa…
Sd Wan Firmware
after 19.2.2
HIGH 8.2
CVE-2020-4462
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnera…
Sterling External Authentication Server
Mitigation only
CRITICAL 9.8
CVE-2020-12684
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a re…
I Net Clear Reports
Mitigation only
HIGH 7.1
CVE-2019-17637
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to …
Debian Linux
after 3.18
MEDIUM 5.5
CVE-2020-4510
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …
Qradar Security Information And Event Manager
after 7.3.2
HIGH 7.5
CVE-2020-5602
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, …
Cpu Module Logging Configuration Tool
after 1.590q
HIGH 7.5
CVE-2020-14940
An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gp…
Tuxguitar
Patch available
HIGH 8.2
CVE-2020-14204
In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTT…
Webfocus Business Intelligence
Mitigation only
MEDIUM 6.5
CVE-2020-8541
OX App Suite through 7.10.3 allows XXE attacks.
Open Xchange Appsuite
No fix yet
MEDIUM 6.7
CVE-2020-13883
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE durin…
Api Manager
after 5.9.0